Cookie policy
CARDO sets two cookies. Both are strictly necessary, and there is no third-party tracking.
Effective TODO_EFFECTIVE_DATE
Draft, not for publication. The legal entity, registered address, contact addresses and effective date are still placeholders in content/site.ts. This document also needs review by a solicitor before it goes live.
Cookies we use
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
cardo_session | Keeps you signed in. HttpOnly, so it cannot be read by JavaScript. Secure and SameSite in production. | 14 days | Strictly necessary |
cardo_csrf | Protects against cross-site request forgery by pairing a cookie value with a request header. | Session | Strictly necessary |
What we do not use
No analytics cookies, no advertising or retargeting pixels, no social media cookies, no session recording, and no third-party tracking of any kind. The marketing pages you are reading now set no cookies at all.
Why there is no banner
Under the Privacy and Electronic Communications Regulations, consent is required for cookies that are not strictly necessary for a service the user has asked for. Both of ours are strictly necessary: without them you cannot stay signed in, and requests cannot be protected against forgery. Since there is nothing optional to consent to, asking would be theatre.
Controlling cookies
You can block or delete cookies in your browser settings. Blocking these two will prevent you from signing in, because there is no other way for the service to recognise your session.
For everything else we do with personal data, see the privacy policy.